Courseiva
Security Engineering →mediumMultiple Select

CAS-004 Security Engineering Practice Question

A security architect is designing a PKI for a large enterprise that issues certificates to thousands of users and devices. The architect wants to implement a mechanism to efficiently check certificate revocation status without requiring clients to download a full CRL. Which TWO technologies should be considered?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

OCSP stapling

Option C (OCSP stapling) is correct because it lets the server obtain a signed, time-stamped OCSP response from the CA and present it during the TLS handshake, so clients get revocation status without contacting the OCSP responder themselves, reducing latency and load. Option D (Online Certificate Status Protocol, OCSP) is correct because it is the standard protocol for querying a responder about a single certificate's revocation status, returning good, revoked, or unknown, which avoids downloading an entire CRL. Option A (CRL distribution points) is not appropriate here because it points clients to full CRLs, which is exactly the bulk-download behavior the architect wants to avoid. Option B (certificate transparency logs) is unrelated to revocation checking; CT logs provide public auditability of issued certificates, not revocation status. Option E (delta CRL) still relies on CRL downloads (a base CRL plus deltas), so it does not meet the goal of avoiding full CRL retrieval.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    CRL distribution points

    Why it's wrong here

    CRL distribution points merely advertise where a full CRL can be fetched, so clients still download that entire list rather than querying a single certificate's status. They are tempting because they are the standard way to locate revocation data, and would be correct when distributing CRLs across multiple CAs or partitions, not for avoiding full-CRL retrieval.

  • ✗

    Certificate transparency logs

    Why it's wrong here

    Certificate transparency logs provide public append-only auditing of issued certificates to detect mis-issuance; they hold no revocation data, so they cannot answer whether a certificate is revoked. They are tempting because they are certificate-related and improve PKI assurance, and would be correct for monitoring unauthorised issuance, not for revocation checking.

  • ✓

    OCSP stapling

    Why this is correct

    OCSP stapling lets the server fetch a signed, timestamped revocation response and present it during the TLS handshake, so clients avoid downloading the full CRL or contacting the OCSP responder directly. This satisfies the stem's constraint of efficient revocation checking without full CRL downloads, while reducing latency and privacy leakage.

  • ✓

    Online Certificate Status Protocol (OCSP)

    Why this is correct

    OCSP queries a responder for the revocation status of a single certificate, returning a signed good, revoked, or unknown response. This satisfies the stem's constraint of avoiding full CRL downloads, since clients no longer retrieve and parse the entire list. It scales efficiently across thousands of user and device certificates.

  • ✗

    Delta CRL

    Why it's wrong here

    Delta CRLs publish only changes since a base CRL, so clients still require that base CRL to reconstruct full revocation state; they reduce, not eliminate, full-CRL downloads. They are tempting because they cut bandwidth for frequent updates, and would be correct alongside a base CRL in a bandwidth-constrained hierarchy, not as the on-demand per-certificate check the scenario demands.

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.